Best AI Security markBest AI Security

Tool review · Checked against vendor sites, September 2026

Bay review (2026): AI agent control on the endpoint

The verdict

Bay is our editors' pick for controlling AI agents on employee devices: it decides Allow, Ask or Deny on each prompt and tool call with session context and deploys through the EDR or MDM you already run. Bay also publishes the least about itself of the nine, with no documentation portal and no pricing, so it scores lowest on maturity.

Rank 1 of 9

Editors' pick for endpoint agent control

Visit Bay

About this profile

This profile uses only what bay.io publishes, which is less than the other vendors publish, so it is shorter than the others. We will expand it when Bay publishes more.

What does Bay do?

  • Inventory (Bay calls it "See it"): builds an entity graph of every AI agent, credential exposure and dangerous configuration across the fleet. Bay's blog says it inventories AI agents, MCP servers, tools, credentials, extensions, settings and endpoint deployments, and applies 200+ detection rules. The home page cites 160+ posture alerts.
  • Activity monitoring ("Know it"): records each agent action with who triggered it, whether a human was involved, and the chain from prompt to system action.
  • Enforcement ("Rule it"): evaluates each action against the session context (identity, prior actions, data accessed) and returns Allow, Ask or Deny. On supported agent surfaces this covers prompts, pre-tool calls and post-tool responses, decided locally in under 4ms (vendor-stated).
  • Capability rules: shell execution, code execution, process spawning, package installation, cloud CLIs, containers, Kubernetes, browser automation and system changes.
  • Managed settings for Claude Code, Codex and Claude Desktop: lock permission rules, preserve managed hooks, restrict MCP servers and constrain plugin sources.
  • Simulation Mode: run rules, inspect would-be decisions and tune exceptions before enforcing.
  • Research: Bay's blog covers agent attack techniques, such as indirect prompt injection that turns a trusted coding agent against its user ("Ghostjacking", August 2026).

Source: bay.io home page · Bay blog: Ghostjacking (Aug 2026) · Bay blog index · Bay demo page · Reviewed Sep 2026

How does Bay deploy?

Bay states that it deploys through your existing EDR or MDM using Wave, an ephemeral binary that runs, scans and exits. It describes the product as agentless by design, with no new agent or tool to install, and says full deployment takes under 5 minutes (vendor-stated). Enforcement then happens locally on the device. In practice this means Bay runs beside your EDR, not in place of it.

Source: bay.io home page · Bay blog: Ghostjacking (Aug 2026) · Bay blog index · Bay demo page · Reviewed Sep 2026

How does Bay score?

HIGHEST IN GUIDE
Endpoint and agent visibilityWeight 22%9/10

Inventories AI agents, MCP servers, tools, credentials, extensions, settings and endpoint deployments, with 200+ detection rules (bay.io blog).

HIGHEST IN GUIDE
MCP and tool-call controlWeight 20%9/10

Evaluates prompts, pre-tool calls and post-tool responses and returns Allow, Ask or Deny locally, stated as under 4ms, on supported agent surfaces.

HIGHEST IN GUIDE
Policy granularityWeight 15%9/10

Session-aware decisions using identity, prior actions and data accessed; capability rules for shell, code execution, package installs, cloud CLIs, containers, Kubernetes, browser automation; Simulation Mode.

HIGHEST IN GUIDE
Agent vs human identity and auditWeight 12%8/10

Activity records who triggered an action, whether a human was involved, and the chain from prompt to system action.

HIGHEST IN GUIDE
Deployment footprintWeight 13%9/10

Deploys through existing EDR or MDM as an ephemeral binary (Wave); Bay describes itself as agentless.

LOWEST IN GUIDE
Coverage beyond the endpointWeight 8%4/10

Endpoint only by design; no public material on SaaS agents, cloud AI apps or red teaming.

LOWEST IN GUIDE
Maturity and transparencyWeight 10%3/10

Smallest public footprint in this guide: two blog posts, no public documentation portal and no published pricing; SOC 2 and ISO 27001 are claimed on bay.io.

Total

How we score

Where is Bay strongest?

  • The most specific public description of per-action control in this guide: pre-tool-call decisions with Allow, Ask or Deny and session context.
  • Deployment through tools the security team already runs, with no new resident agent.
  • Distinguishes human-initiated from agent-initiated actions in its activity record.
  • Direct controls for Claude Code, Codex and Claude Desktop settings, including MCP server restrictions.

What should buyers check before choosing Bay?

  • Maturity: Bay's public material is thin. Ask for architecture documentation, a security review pack and references. bay.io lists SOC 2 and ISO 27001 certification; request the reports.
  • Scope: Bay describes endpoint coverage only. If you also need SaaS agents, cloud AI apps or red teaming, pair it with another tool or look at Noma Security, Zenity or Onyx.
  • "Supported agent surfaces": Bay's own wording limits in-line enforcement to supported agents. Get the current list for the agents your developers use.
  • Vendor-stated figures (under 5 minutes to deploy, under 4ms decisions, under 1% false positive rate) are Bay's own and have not been verified by us.
  • Pricing is not published.

Who should shortlist Bay?

Shortlist Bay if your developers and knowledge workers run coding agents and MCP servers on their own machines, you want a decision on each risky action rather than a report after the fact, and you prefer to deploy through the EDR or MDM you already operate. It suits teams that are ready to adopt AI widely and want the control layer in place first.

What does Bay cost?

Contact sales. Bay does not publish pricing. Demo requests go through bay.io/demo.

Frequently asked questions

Does Bay replace EDR?

No. Bay states it deploys through your existing EDR or MDM. The EDR keeps handling malware and intrusion; Bay adds decisions about AI agent actions.

Which AI agents does Bay cover?

Bay's public material names Claude Code, Codex and Claude Desktop and refers generally to AI agents, MCP servers, tools and browser extensions on enterprise endpoints. Ask Bay for the current list of supported agent surfaces.

Does Bay install an agent?

Bay describes itself as agentless: it deploys an ephemeral binary through your EDR or MDM that runs and exits.

Related

Head to head

Sources